IP Library Granted Patent US 11,595,437
Granted Patent B1
US 11,595,437 · App. 17/235,546 · Granted Feb 28, 2023

Method and system for stopping multi-vector phishing attacks using cloud powered endpoint agents

Inventor: Atif Mushtaq (San Ramon, CA)
Assignee: SLASHNEXT, INC.
H04L63/1483H04L41/16H04L41/22H04L63/1408H04L63/1416H04L63/1425H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,437
App. No.
17/235,546
Granted
Feb 28, 2023
Kind
B1
Abstract

An endpoint protection system is provided. The system comprises: an endpoint agent deployed to an endpoint device, wherein the endpoint agent is built-into one or more existing applications running on the endpoint device and is configured to capture network session activity between the endpoint device and one or more internet servers to detect a phishing attack using a set of machine learning algorithm trained classifiers, and block the phishing attack; and an endpoint management system in remote communication with the endpoint agent, wherein the endpoint management system is configured to train and develop the set of classifiers, and receive information about the detected phishing attack and an incident report from the endpoint agent, the endpoint agent provides a graphical user interface running on the endpoint device allowing an end user to configure one or more protections provided by the endpoint agent.

Claims (18)

1. An endpoint protection system comprising:

(a) an endpoint agent deployed to an endpoint device, wherein the endpoint agent is built into one or more existing applications running on the endpoint device and wherein the endpoint device comprises at least one processor, a memory, and a computer program including instructions executable by the at least processor to implement the endpoint agent that is configured to detect a phishing attack using a set of machine learning algorithm trained classifiers, block the phishing attack, provide a graphical user interface (GUI) running on the endpoint device allowing an end user to configure one or more protections provided by the endpoint agent and provide a safe preview of the blocked phishing attack within the GUI, wherein the safe preview of the blocked phishing attack is generated based on artifacts from a virtual browser memory by loading a potentially malicious webpage into the virtual browser memory, wherein the potentially malicious webpage is identified based on a network session activity between the endpoint device and one or more internet servers; and

(b) an endpoint management system in remote communication with the endpoint agent, wherein the endpoint management system comprises at least one processor configured to execute instructions stored on a memory of the endpoint management system to train and develop the set of classifiers.

2. The endpoint protection system of claim 1 , wherein the endpoint agent is configured to further send a request to the endpoint management system for determining whether the potentially malicious webpage is benign or malicious.

3. The endpoint protection system of claim 1 , wherein the potentially malicious webpage is further analyzed using a virtual browser technique.

4. The endpoint protection system of claim 3 , wherein the virtual browser technique comprises loading the potentially malicious webpage into the virtual browser memory and extracting forensic intelligence on a behavior of the potentially malicious webpage.

5. The endpoint protection system of claim 1 , wherein the one or more existing applications include a web browser and the endpoint agent is a web browser extension.

6. The endpoint protection system of claim 1 , wherein the endpoint management system is configured to further receive information about the detected phishing attack and an incident report from the endpoint agent.

7. A method for providing endpoint protection comprising:

deploying an endpoint agent to an endpoint device, wherein the endpoint agent is built into one or more existing applications running on the endpoint device and wherein the endpoint device comprises at least one processor, a memory, and a computer program including instructions executable by the at least processor to implement the endpoint agent;

detecting a phishing attack using a set of machine learning algorithm trained classifiers;

blocking, by the endpoint agent, the phishing attack and providing a graphical user interface (GUI) running on the endpoint device allowing an end user to configure one or more protections provided by the endpoint agent, wherein a safe preview of the blocked phishing attack is provided within the GUI and wherein the safe preview of the blocked phishing attack is generated based on artifacts from a virtual browser memory by loading a potentially malicious webpage into the virtual browser memory, wherein the potentially malicious webpage is identified based on a network session activity between the endpoint device and one or more Internet servers; and

training and developing the set of classifiers in an endpoint management system that is in remote communication with the endpoint agent.

8. The method of claim 7 , further comprising sending a request to the endpoint management system for determining whether the potentially malicious webpage is benign or malicious.

9. The method of claim 7 , further comprising analyzing the potentially malicious webpage using a virtual browser technique.

10. The method of claim 9 , wherein the virtual browser technique comprises loading the potentially malicious webpage into the virtual browser memory and extracting forensic intelligence on a behavior of the potentially malicious webpage.

11. The method of claim 7 , wherein the one or more existing applications include a web browser and the endpoint agent is a web browser extension.

12. The method of claim 7 , further comprising receiving, at the endpoint management system, information about the detected phishing attack and an incident report from the endpoint agent.

Assignments (4)
CHANGE OF NAME Recorded Apr 16, 2026
From: SLASHNEXT, INC.
To: SLASHNEXT, LLC
Reel/Frame 075409/0484 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2026
From: SLASHNEXT, LLC
To: VARONIS SYSTEMS, INC.
Reel/Frame 075409/0567 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2023
From: MUSHTAQ, ATIF
To: SLASHNEXT, INC.
Reel/Frame 062311/0056 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2021
From: MUSHTAQ, ATIF
To: SLASHNEXT, INC.
Reel/Frame 056334/0709 →
Continuity (1)
Provisional Application 63013905 · Apr 22, 2020
Cited By (21)
US 1,074,730 US 1,076,966 US 1,079,733 US 1,083,951 US 12,219,346 US 12,225,046 US 12,229,246 US 12,231,464 US 12,348,564 US 12,388,866 US 12,388,870 US 12,445,485 US 12,519,806 US 12,531,903 US 12,536,279 US 12,537,856 US 12,547,713 US 12,561,430 US 12,592,964 US 12,682,057 US 12,699,578